ClickFix attacks infecting PCs and Macs are going viral

← Back to the feed

ClickFix attacks infecting PCs and Macs are going viral

Ars Technica · 5 hours ago

ClickFix, a social-engineering attack technique, has gone from a rare threat to a mainstream infection method hitting both Windows and Mac users, according to security researchers. The attack tricks visitors of compromised websites into copying and running a malicious command via a fake CAPTCHA prompt, exploiting the fact that many users have become desensitised to confusing or burdensome online instructions, making them easy targets regardless of technical skill.

The method requires little more than a hacked website, a spoofed CAPTCHA overlay and a single terminal command, which victims are told to paste into Windows Run, PowerShell or the macOS terminal. Security firm BlueVoyant noted that switching to ClickFix removes the need for code-signing certificates and expands the pool of potential victims beyond those actively searching for specific software. Researchers at Jamf, Cisco Talos and Netskope have documented variants bypassing macOS Gatekeeper protections, abusing Google Sheets, and using blockchain-based smart contracts for control infrastructure, with one Netskope-tracked campaign involving around 5,400 compromised sites; even state-sponsored groups such as Russia's Sandworm have adopted the technique.

  • ClickFix scam tricks users into running malicious terminal commands
  • Now infects both Windows and Mac users widely
  • Attackers, including state-backed groups, exploit user fatigue with online prompts

Trending Weird & Viral

Read the full article at the source →